Home

Description

A flaw was found in gnome-remote-desktop. Once gnome-remote-desktop listens for RDP connections, an unauthenticated attacker can exhaust system resources and repeatedly crash the process. There may be a resource leak after many attacks, which will also result in gnome-remote-desktop no longer being able to open files even after it is restarted via systemd.

PUBLISHED Reserved 2025-05-21 | Published 2025-05-22 | Updated 2025-11-20 | Assigner redhat




HIGH: 7.4CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:N/A:H

Problem types

Uncontrolled Resource Consumption

Product status

Default status
affected

0:47.3-2.el10_0 (rpm) before *
unaffected

Default status
affected

0:0.1.8-4.el8_10 (rpm) before *
unaffected

Default status
affected

0:0.1.6-9.el8_2.1 (rpm) before *
unaffected

Default status
affected

0:0.1.8-4.el8_4 (rpm) before *
unaffected

Default status
affected

0:0.1.8-4.el8_4 (rpm) before *
unaffected

Default status
affected

0:0.1.8-4.el8_6 (rpm) before *
unaffected

Default status
affected

0:0.1.8-4.el8_6 (rpm) before *
unaffected

Default status
affected

0:0.1.8-4.el8_6 (rpm) before *
unaffected

Default status
affected

0:0.1.8-4.el8_8 (rpm) before *
unaffected

Default status
affected

0:0.1.8-4.el8_8 (rpm) before *
unaffected

Default status
affected

0:40.0-11.el9_6 (rpm) before *
unaffected

Default status
affected

0:40.0-10.el9_0 (rpm) before *
unaffected

Default status
affected

0:40.0-10.el9_2 (rpm) before *
unaffected

Default status
affected

0:40.0-11.el9_4 (rpm) before *
unaffected

Timeline

2025-05-21:Reported to Red Hat.
2025-05-21:Made public.

References

access.redhat.com/errata/RHSA-2025:10631 (RHSA-2025:10631) vendor-advisory

access.redhat.com/errata/RHSA-2025:10635 (RHSA-2025:10635) vendor-advisory

access.redhat.com/errata/RHSA-2025:10742 (RHSA-2025:10742) vendor-advisory

access.redhat.com/errata/RHSA-2025:11403 (RHSA-2025:11403) vendor-advisory

access.redhat.com/errata/RHSA-2025:11404 (RHSA-2025:11404) vendor-advisory

access.redhat.com/errata/RHSA-2025:11405 (RHSA-2025:11405) vendor-advisory

access.redhat.com/errata/RHSA-2025:11406 (RHSA-2025:11406) vendor-advisory

access.redhat.com/errata/RHSA-2025:11407 (RHSA-2025:11407) vendor-advisory

access.redhat.com/errata/RHSA-2025:11408 (RHSA-2025:11408) vendor-advisory

access.redhat.com/errata/RHSA-2025:11418 (RHSA-2025:11418) vendor-advisory

access.redhat.com/security/cve/CVE-2025-5024 vdb-entry

bugzilla.redhat.com/show_bug.cgi?id=2367717 (RHBZ#2367717) issue-tracking

gitlab.gnome.org/...nome-remote-desktop/-/merge_requests/321

cve.org (CVE-2025-5024)

nvd.nist.gov (CVE-2025-5024)

Download JSON